Why this month's Microsoft patch release is a doozy
| Source: Ars Technica AI
Tags: Microsoft, CVE, Exchange Server, zero-day, AI-assisted attacks, vulnerability disclosure, enterprise security
Microsoft's September 2026 patch fixes a record 972 vulnerabilities (112 critical), more than doubling last year's pace — a direct response to AI-accelerated vulnerability discovery that is forcing the entire industry into a new security baseline.
Details
Microsoft's September patch release sets an unprecedented record at 972 vulnerabilities fixed (997 including Edge/Chromium), with 112 rated critical. The scale reflects a pattern: just two months ago the record was 570, last month 620. At the current pace, Microsoft will fix more bugs in 2026 than in 2023, 2024, and 2025 combined. The driver is AI. Major AI labs and cloud providers — OpenAI, Anthropic, AWS, Google, Microsoft, and 100 others — co-signed an open letter two weeks ago warning of a narrowing patching window ahead of expected AI-enabled exploit waves. Researcher Dustin Childs of Zero Day Initiative describes this as the 'new normal': faster patch throughput now, but the active-exploit tsunami hasn't arrived yet. Most urgent in this release: CVE-2026-55007 in Exchange Server allows remote unauthenticated code execution via a malicious Visio email attachment — zero user interaction required. CVE-2026-80097 is a privilege escalation in Microsoft Authenticator itself, described as 'the worst type' by Childs. Two actively-exploited zero-days hit the Windows update service and Advanced Local Procedure call. SharePoint carries roughly 17 distinct vulnerabilities. For enterprises, this is an all-hands patch cycle. Exchange, SharePoint, and Authenticator are core infrastructure, and unauthenticated RCE on Exchange is the kind of critical that gets breached within days of public knowledge.